Exploring the State of State and Local Cyber Resources

State and local organizations are highly targeted by cyber criminals due to the value of the data they hold and the criticality of the systems they operate. In 2024, there were over 40,000 potential cyber attacks targeting state, local, and tribal governments. Despite this very real threat, these same organizations are largely underfunded and understaffed when it comes to cyber protection.

The federal government has looked to fill this gap between risk and preparedness. The State and Local Cybersecurity Grant Program (SLCGP) was established under the Infrastructure Investment and Jobs Act of 2021, providing (when combined with the Tribal Cybersecurity Grant Program) $1 billion in funding available over four years for state, local, tribal, and territorial cybersecurity efforts. This program ended at the close of the 2025 government fiscal year but received a short-term extension under the stopgap funding agreement that reopened the government in November 2025. Continue reading

A Look at Homeland Security Innovation Strategy

The mission of the Department of Homeland Security (DHS) is to "secure the nation from the many threats we face." An underlooked key to this statement is the word "many." Agencies under the Department are responsible for managing our borders, protecting the nation from cyber and physical threats, and supporting recovery from natural disasters and cyber attacks. To meet this mission, DHS has been embracing innovative approaches and emerging technology to supplement the efforts of the workforce charged with meeting these varied threats.

The DHS Innovation, Research & Development Strategic Plan laid out eight scientific areas as focal points for research to support national security:

  • Advanced sensing
  • AI and autonomous systems
  • Biotechnology
  • Climate change
  • Communications and networking
  • Cybersecurity
  • Data integration, analytics, modeling, and simulation
  • Digital identity and trust

As part of its work in each of these areas, DHS will be researching how emerging technology can support mission efforts as well as the risks technology poses to national security. In this blog, we'll take a look at the activity in a couple of these areas. Continue reading

As Students Go Back to School Threat Actors Go Back to Work

School systems are at high risk for cyber attacks because threat actors know they are traditionally underfunded and understaffed, meaning many vulnerabilities may remain open.

Once in, hackers have access to incredibly valuable and personal information on children and their families, leading to ransom requests. In fact, the education sector is now the number one sector for ransomware attacks, with a 44% increase in the past year.

The eye-opening statistics don't stop there.

  • The education sector sees an average of 2,297 attacks weekly.
  • By the end of 2021, nearly one in three U.S. districts had experienced a breach.
  • The monetary losses to school districts following a cyber incident range from $50,000 to $1 million.
  • Six months into 2023, at least 120 schools faced a ransomware attack, compared to 188 in all of 2022.

Continue reading

Strengthening Cyber Resilience With Collaboration

Today's organizations know that stopping 100% of cyber-attacks is not a realistic goal. Rather, the focus has shifted to cyber resilience, "the ability to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises on systems that use or are enabled by cyber resources."

A critical pillar in becoming resilient is communication and collaboration. The Cyber EO focused on improving the nation's cybersecurity and highlighted the need to improve collaboration with threat intelligence sharing between public and private organizations as well as the creation of cross-government cyber boards. In recent months, key strides have been made in facilitating information sharing around cyber best practices, resource availability, as well as process and policy. Continue reading

Taming the Superpower of Data – Data Privacy in Our Digital World

Data helps organizations make more informed decisions about how they serve their customers. Data informs policy and procedures and feeds more personalized interaction with people. But with great power comes vast responsibility. The data that organizations hold can be incredibly personal. It's more than just someone's social security number. It is information about where people live, work, shop, keep their money, get their news, and more. Individuals should have control over who knows this information and, if they do have it, how they use it. However, most of us do little to understand our privacy rights beyond blindly clicking a checkbox that allows sites to collect information about our activities.

Data privacy practices ensure that the data shared by customers is only used for its intended purpose. A multitude of laws, including the Health Insurance Portability and Accountability Act (HIPAA), Electronic Communications Privacy Act (ECPA), Children's Online Privacy Protection Act (COPPA), and General Data Protection Regulation (GDPR) have been enacted to provide guidelines to organizations and promises of data privacy to individuals.

Continue reading